Legal

Privacy Policy

Last updated: May 26, 2026

This Privacy Policy explains how danielmaze.com and projectrealitycheck.com (together, "the Sites") collect, use, store and protect personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable international privacy laws.

1. Data Controller

Maze Films BV, Ninoofsesteenweg 797, 1703 Schepdaal, Belgium. VAT: BE 0891.138.010. For any privacy request, write to privacy@danielmaze.com.

2. Personal Data We Collect

Information you provide: name, email address, project title, role, any free-text notes you submit, and (if you book or pay) billing/payment details processed through third-party providers.

Diagnostic data (Reality Check): the answers you select, the resulting category scores, overall score, result type and risk level.

Automatically collected: IP address, country derived from IP, source domain (danielmaze.com or projectrealitycheck.com), referrer URL, landing page, and UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) plus first-touch and last-touch equivalents.

Cookies and local storage: a small set of strictly necessary identifiers (e.g. a Reality Check session ID, attribution values). The Sites do not currently load third-party analytics, advertising or tracking scripts, so no consent banner is shown. If that changes, a compliant consent flow will be added before any non-essential script loads.

3. How We Use Personal Data

  • To send you your Reality Check result by email, when you ask us to.
  • To send occasional content updates and film-industry insights, only if you separately opt in.
  • To schedule and confirm bookings, deliver consultations, process payments and respond to enquiries.
  • To produce aggregated analytics about how the Sites and the diagnostic tool are used.
  • To protect against abuse, spam and fraud, and to comply with legal obligations.

We do not sell personal data.

4. Legal Bases for Processing

  • Consent (Art. 6(1)(a)) — for sending you your Reality Check result and for sending marketing/content updates. Each is a separate, opt-in checkbox.
  • Contract (Art. 6(1)(b)) — for delivering bookings, consultations and paid services.
  • Legitimate interest (Art. 6(1)(f)) — for aggregated analytics, attribution, security and fraud prevention. We balance this against your rights and use the minimum data necessary.
  • Legal obligation (Art. 6(1)(c)) — for tax, accounting and other statutory requirements.

5. Data Sharing

We use the following categories of processors / sub-processors, each bound by GDPR-compliant data-processing terms:

  • Lovable Cloud / Supabase — application hosting, database and authentication.
  • Lovable Email infrastructure — transactional email delivery for system messages.
  • Google (Gmail API) — outbound delivery of the Reality Check result email.
  • Cloudflare — edge hosting and DNS for the Sites.
  • Payment processors and booking platforms used only when you book or pay for a service.

A current list of processors is available on request. We do not share personal data with third parties for their own marketing.

6. Data Retention

  • Reality Check leads and diagnostic answers are kept in identifiable form for up to 24 months. After that, an automated job anonymizes the record — email, name, project title and free-text answers are removed, while aggregated scoring and source data are kept for analytics.
  • Marketing-consent records are kept for as long as you remain opted in, plus a short evidentiary period after you unsubscribe.
  • Suppression list (unsubscribes, bounces, complaints) is kept for as long as necessary to honour your choice.
  • Invoices and transaction records are kept for the period required by Belgian/EU tax law (currently 7–10 years).
  • Server logs and security data are kept for a short period (typically up to 90 days) unless needed for an active investigation.

7. Your Rights (GDPR)

Under GDPR you have the right to: access your data, ask for correction or deletion, request restriction or portability, object to processing based on legitimate interest, and withdraw any consent at any time without affecting pre-withdrawal processing.

To exercise any of these rights, email privacy@danielmaze.com. We aim to respond within 30 days.

Withdrawing marketing consent is one click — every content-update email contains an unsubscribe link, and you can also email us. Unsubscribing updates your stored consent state and adds your address to a suppression list so no further marketing is sent.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, dataprotectionauthority.be).

8. International Transfers

Data may be transferred outside the EU by third-party providers under GDPR safeguards such as Standard Contractual Clauses.

9. Data Security

We use industry-standard technical and organizational measures to protect your data. No system is entirely secure; use of this site is at your own risk.

10. Updates to This Policy

This Policy may be updated at any time. The revision date will be posted at the top of this page.